gateway: concurrent ACME rotation is only best-effort serialized
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 35/100
- Tipo di issue
- Bug
- Chiarezza
- Da chiarire
- Stato di attività
- Tranquilla
- Stack tecnologico
- rust
- Ambito
- distributed-systems
Direzione di ricerca
Inizia leggendo l’RPC RotateAcmeCredentials, il comportamento di global/acme_rotation_lock in WaveKV e il contesto aggiuntivo in #935. Confronta le direzioni elencate relative a CAS o fenced-lock, leader-routing e verifica post-rotazione con il comportamento attuale del gateway. Done dovrebbe impedire rotazioni concorrenti oppure rilevare e recuperare in modo affidabile dalle divergenze di CAA e credenziali.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Follow-up to #935.
RotateAcmeCredentials is serialized across nodes by a TTL lock in WaveKV (global/acme_rotation_lock). WaveKV is last-writer-wins without compare-and-swap, so the lock is acquired by read-then-write: two nodes calling the RPC within a replication gap can both acquire it and rotate concurrently.
Impact
If two rotations interleave, CAA records end up pinned to one node's new account while LWW keeps the other node's credential in KV. Since #935 the state is recoverable — the published credential wins LWW and one SetCaa run re-pins every domain to it — but issuance is broken until an operator notices and intervenes.
The constraint "rotate through one gateway at a time" is advisory only: the admin endpoint uses a shared bearer token with no per-method authorization, so nothing enforces it.
Possible directions
- Add CAS (or a fenced-lock primitive) to WaveKV and make the rotation lock a real mutex.
- Route rotation to a designated leader node instead of accepting it on any gateway.
- At minimum: automatic post-rotation verification that the published credential's
accounturimatches every domain's CAA, alerting on divergence (see the CAA reconciliation issue).
- Lingua principale
- Rust
- Stelle
- 550
- Fork
- 97
- Merge medio
- 19h 22m
- PR unite (30g)
- 109
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Dstack-TEE/dstack
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 30/100
Dstack-TEE/dstack#1301 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
Dstack-TEE/dstack#1300 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
Dstack-TEE/dstack#1299 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
Dstack-TEE/dstack#1298 ·
-
P0
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
Dstack-TEE/dstack#1297 ·
Tutte le issue di Dstack-TEE/dstack
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
ontola/atomic-server#1625 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
VirusTotal/yara-x#777 ·
-
has_tail_capacity wraps and get_writable_raw_unchecked commits raw_len before the bounds check Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
stratum-mining/stratum#2404 ·
-
bug ci good first issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100